In GitLab CE/EE versions 13.12 to 18.2.8, 18.3 to 18.3.4 and 18.4 to 18.4.2 a high severity vulnerability CVE-2025-10004 was detected. This vulnerability allows attackers to cause unresponsiveness or severe performance degradation by sending crafted GraphQL queries requesting large repository blobs. To address this issue, users should upgrade GitLab CE/EE to versions 18.4.2, 18.3.4 or 18.2.8. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-10004.
GitLab: Denial of Service via Large GraphQL Repository Blob Queries
by the Hossted team
13.10.2025